Translating risk insights into actionable protection: leveling up security posture with Cloudflare and Mastercard (opens in new tab)
Organizations are expanding their Internet-facing assets faster than they can inventory and secure them, leaving shadow domains, forgotten hosts, and vulnerable services exposed. Cloudflare and Mastercard plan to integrate RiskRecon attack surface intelligence into Cloudflare Security Insights to continuously discover these risks and recommend remediation. The integration is intended to shift security from periodic audits toward ongoing visibility and protection. ## Attack Surface Intelligence - Mastercard RiskRecon maps an organization’s public Internet footprint using outside-in, publicly available data. - It can identify shadow IT, forgotten subdomains, unauthorized cloud servers, exposed services, weak authentication, outdated software, and encryption problems. - A 2025 study of 15,896 breached organizations found that major posture gaps made companies: - 5.3 times more likely to experience ransomware. - 3.6 times more likely to suffer a data breach. ## Combining Discovery with Cloudflare Protection - RiskRecon identifies security gaps, while Cloudflare provides controls to address them. - Discovered assets can be routed through Cloudflare’s proxy without changing the underlying application or website. - In a sample covering approximately 388,000 organizations and 18 million systems, Cloudflare-proxied systems showed: - 53% fewer software vulnerabilities. - 58% fewer SSL/TLS issues. - 98% fewer instances of malicious behavior. ## Finding Shadow Domains and Unprotected Hosts - Cloudflare Security Insights already detects issues for domains that are proxied through Cloudflare, including DNS errors, weak encryption, and inactive WAF rules. - The Mastercard integration will extend visibility to domains and hosts that Cloudflare does not yet know about or protect. - RiskRecon continuously profiles organizations’ Internet footprints and identifies associated domains, hosts, and software stacks. - Assets will receive criticality ratings: - **High:** Sensitive-data systems, authenticated applications, databases, or remote-access services. - **Medium:** Brochure sites adjacent to high-criticality systems. - **Low:** Brochure sites with no proximity to critical systems. ## Turning Findings into Remediation - Security Insights is designed to recommend concrete fixes rather than only report vulnerabilities. - Suggested actions may include: - Enabling the Cloudflare proxy for discovered zones and hosts. - Activating WAF, DDoS, and bot protection. - Enforcing stronger TLS settings. - Applying controls such as API Shield or specific WAF rules. - Future plans include risk scoring and AI-assisted diagnosis that correlates findings with traffic and recommends targeted configurations. ## Availability - The planned integration is expected to enter preview in the third quarter of 2026 for Information Security practitioners on pay-as-you-go and Enterprise accounts. The partnership’s practical goal is to help organizations discover assets they did not know existed, prioritize the most dangerous exposures, and protect them through Cloudflare before attackers exploit them.